Vulnerabilities (CVE)

Filtered by CWE-79
Total 45369 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-27695 1 Openmaint 1 Openmaint 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Floor, or others in the Name and Code Parameters.
CVE-2021-27676 1 Centreon 1 Centreon 2026-07-09 3.5 LOW 5.4 MEDIUM
Centreon version 20.10.2 is affected by a cross-site scripting (XSS) vulnerability. The dep_description (Dependency Description) and dep_name (Dependency Name) parameters are vulnerable to stored XSS. A user has to log in and go to the Configuration > Notifications > Hosts page.
CVE-2021-27332 1 Casap Automated Enrollment System Project 1 Casap Automated Enrollment System 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the class_name parameter to update_class.php.
CVE-2021-26787 1 Genesys 1 Workforce Management 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
A cross site scripting (XSS) vulnerability in Genesys Workforce Management 8.5.214.20 can occur (during record deletion) via the Time-off parameter.
CVE-2021-25878 1 Youphptube 1 Youphptube 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoName parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.
CVE-2021-25876 1 Youphptube 1 Youphptube 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the u parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.
CVE-2021-25875 1 Youphptube 1 Youphptube 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the searchPhrase parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.
CVE-2021-25680 1 Adtran 3 Netvanta 7060, Netvanta 7100, Personal Phone Manager 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These issues impact at minimum versions 10.8.1 and below but potentially impact later versions as well since they have not previously been disclosed. Only version 10.8.1 was able to be confirmed during primary research. NOTE: The affected appliances NetVanta 7060 and NetVanta 7100 are considered End of Life and as such this issue will not be patched.
CVE-2021-25679 1 Adtran 3 Netvanta 7060, Netvanta 7100, Personal Phone Manager 2026-07-09 3.5 LOW 5.4 MEDIUM
The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues. These issues impact at minimum versions 10.8.1 and below but potentially impact later versions as well since they have not previously been disclosed. Only version 10.8.1 was able to be confirmed during primary research. NOTE: The affected appliances NetVanta 7060 and NetVanta 7100 are considered End of Life and as such this issue will not be patched.
CVE-2021-25299 1 Nagios 1 Nagios Xi 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal his/her session cookies or it can be chained with the previous bugs to get one-click remote command execution (RCE) on the Nagios XI server.
CVE-2020-36012 1 Bdtask 1 Multi-store 2026-07-09 3.5 LOW 4.8 MEDIUM
Stored XSS vulnerability in BDTASK Multi-Store Inventory Management System 1.0 allows a local admin to inject arbitrary code via the Customer Name Field.
CVE-2020-36011 1 Qdocs 1 Smart Hospital 2026-07-09 3.5 LOW 4.8 MEDIUM
A cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote attacker to inject arbitrary code via the Name, Guardian Name, Email, Address, Remarks, or Any Known Allergies field.
CVE-2020-35854 1 Textpattern 1 Textpattern 2026-07-09 3.5 LOW 4.8 MEDIUM
Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.
CVE-2020-35305 1 Gollum Project 1 Gollum 2026-07-09 N/A 6.1 MEDIUM
Cross site scripting (XSS) in gollum 5.0 to 5.1.2 via the filename parameter to the 'New Page' dialog.
CVE-2020-35275 1 Coastercms 1 Coastercms 2026-07-09 3.5 LOW 5.4 MEDIUM
Coastercms v5.8.18 is affected by cross-site Scripting (XSS). A user can steal a cookie and make the user redirect to any malicious website because it is trigged on the main home page of the product/application.
CVE-2020-35274 1 Dotcms 1 Dotcms 2026-07-09 3.5 LOW 4.8 MEDIUM
DotCMS Add Template with admin panel 20.11 is affected by cross-site Scripting (XSS) to gain remote privileges. An attacker could compromise the security of a website or web application through a stored XSS attack and stealing cookies using XSS.
CVE-2020-35262 1 Digisol 2 Dg-hr3400, Dg-hr3400 Firmware 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in Digisol DG-HR3400 can be exploited via the NTP server name in Time and date module and "Keyword" in URL Filter.
CVE-2020-29477 1 Invisioncommunity 1 Community 2026-07-09 3.5 LOW 4.8 MEDIUM
Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field. This vulnerability can allow an attacker to inject the XSS payload in Field Name and each time any user will open that, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.
CVE-2020-29247 1 Wondercms 1 Wondercms 2026-07-09 3.5 LOW 4.8 MEDIUM
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Admin Panel. An attacker can inject the XSS payload in Page keywords and each time any user will visit the website, the XSS triggers, and the attacker can able to steal the cookie according to the crafted payload.
CVE-2020-29231 1 Egavilanmedia 1 User Registration And Login System With Admin Panel 2026-07-09 3.5 LOW 5.4 MEDIUM
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page. This vulnerability can result in the attacker injecting the XSS payload in Admin Full Name and each time admin visits the Profile page from the admin panel, the XSS triggers.